Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-27932
HistoryMar 14, 2024 - 10:53 p.m.

Design/Logic Flaw

2024-03-1422:53:54
PRIOn knowledge base
www.prio-n.com
15
deno
javascript
typescript
webassembly
logic flaw
token leak
security patch

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to version 1.40.4, Deno improperly checks that an import specifier’s hostname is equal to or a child of a token’s hostname, which can cause tokens to be sent to servers they shouldn’t be sent to. An auth token intended for example[.]com may be sent to notexample[.]com. Anyone who uses DENO_AUTH_TOKENS and imports potentially untrusted code is affected. Version 1.40.0 contains a patch for this issue

CPENameOperatorVersion
denoeq= >= 1.8.0, < 1.40.4

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Related for PRION:CVE-2024-27932